Terminal Escape Sequence Injection Vulnerability in Onefetch by o2sh
CVE-2026-100866
4.8MEDIUM
What is CVE-2026-100866?
Onefetch versions up to 2.28.1 are susceptible to a terminal escape sequence injection vulnerability. This issue arises from the improper handling of repository information field values, which are outputted to the terminal without the necessary sanitization to remove control characters. Consequently, attackers can exploit this flaw by injecting ANSI/OSC escape sequences into the project manifest version and name fields. When a user runs Onefetch, these escape sequences can manipulate the terminal output, enabling the potential to rewrite window titles, hide text, or invoke emulator-specific actions, thereby compromising the security and usability of the terminal environment.
Affected Version(s)
onefetch 0 <= 2.28.1
